CVE-2026-5358
CRITICALStatic buffer overflow in deprecated nis_local_principal
Title source: cnaDescription
Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API can only be called with a trusted server from the pre-populated cache. The use of a trusted server means no trust boundary is crossed and this is therefore considered a normal bug.
References (1)
Scores
CVSS v3
9.1
EPSS
0.0004
EPSS Percentile
12.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-120
Status
published
Products (1)
The GNU C Library/glibc
< 2.43
Published
Apr 20, 2026
Tracked Since
Apr 21, 2026